ONLINE CARD CHECKER

For both CSCS and Partners' schemes


Go Smart Privacy Notice for Go Smart website and Online Checking Service

Reference Point Ltd is committed to protecting and respecting your privacy. This policy, sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.

We keep certain basic information when you visit our website and recognise the importance of keeping that information secure and letting you know what we will do with it.

Background

We are an IT provider for organisations in the construction industry who issue CSCS cards or CSCS approved cards. The services include this online checking service located on the website www.gosmart.co.uk (“our website”) which allows the data of cardholders in participating card schemes to be checked online upon the input of certain identifying cardholder information. The services also include an App for which there is a separate privacy notice.

For the purposes of the General Data Protection Regulation (GDPR (EU) 2016/679), the Data Protection Act 2018 and any successor legislation (“data protection legislation”):

We are the data controller for the data you enter into our website, information about your use of our website and any correspondence we enter into with you.

If you are a Cardholder, please refer to the privacy notice provided to you by your Card Scheme but note that where a search has been performed using the online check service using your personal data, we will store the search criteria input by the checker.

Contact Details

Our contact details: Reference Point Limited, Shire House, West Common, Gerrards Cross, SL9 7QN +44 (0) 1753 279 927.

Questions, comments and requests regarding this Privacy Notice are welcomed and should be addressed for the attention of our Data Protection Officer. Email: dpo@referencepoint.co.uk.

Information we may collect from you and purpose for processing

Where you contact us for support, we will use your email address and any other contact details you provide for communicating with you. The details of support requested and provided will be logged for our internal records.

We may also ask you for information when you report a problem with our site.

We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them.

If you perform a search using the online check service we will collect and store your IP address and the search criteria you have input into the online check service.

Lawful basis for processing

We will only use your personal data when the law allows us to.

  • We may use your personal data to perform the contract we have entered into with you or in order to take steps at your request to enter into a contract with you (Basis: Art 6(b) GDPR).
  • We and any third parties with whom we share your personal data may also find it necessary to process your data for legitimate interests we pursue (Basis: Art 6(f) GDPR), for example, to improve our services.
  • We may also process your personal data based on compliance with a mandatory legal obligation (Basis: Art 6 (c) GDPR) including, for example, accounting and tax requirements which are subject to strict internal policies (such as retention periods).
  • Where we do not rely on another legal basis, we may process your personal data based on consent you provide (Basis: Art 6(a) GDPR).

The recipients or categories of recipients of personal data

We will share your personal data with third parties where required by law or where we have another legitimate interest in doing so.

We may disclose your personal information to third parties:

  • In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
  • If we are under a duty to disclose or share your personal data in order to comply with any legal obligation. This includes exchanging information with other companies and organisations for the purposes of fraud protection.

Where we store your personal data and transfers out of the EEA

The data that we collect from you will be stored within the UK and may be processed by staff operating within the UK who work for us and any relevant sub-processors.

We will not transfer any data that we collect or receive from you that constitutes personal data outside of the EEA and the UK unless there are appropriate safeguards or an adequacy decision in relation to the transfer as set out in the data protection legislation or the transfer otherwise complies with the data protection legislation. Such transfers may involve, for example, our use of third party services allowing us to send emails or automated SMS messages which make use of facilities in third countries to process and store data.

Security

We will take all steps reasonably necessary to ensure that your data provided to us is treated securely and in accordance with this privacy notice.

All information you provide to us is stored on our or our sub-contractors' secure servers. Where we have given you (or where you have chosen) a password which enables you to access certain parts of the website, you are responsible for keeping this password confidential.

We take steps to protect the information that we receive from you from loss, misuse, and unauthorised access or disclosure. These steps take into account the sensitivity of the information we receive, process and store, and the current state of technology.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do what we reasonably can to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use reasonable procedures and security features to try to prevent unauthorised access.

Retention period and criteria used to determine the retention period

  • We will only retain your personal data for as long as necessary to fulfil the purpose for which it was collected, including for the purposes of satisfying any legal, accounting or reporting requirements.
  • Encrypted back ups: We will retain encrypted back up tapes for a maximum of 3 years from the termination of our contract with you, if any, or from when you cease to use our services. This time limit is set in line with the limitation period for possible legal claims which may require such data in order to be investigated and/or defended against.

Your Rights

You have the right to:

  • Request access to your personal information (commonly known as a "data subject access request"). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected.
  • Request erasure of your personal information (commonly known as “the right to be forgotten”). This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have exercised your right to object to processing.
  • Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your personal information for direct marketing purposes.
  • Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
  • Request the transfer of your personal information to another party.

Where our processing is based on your explicit consent to our processing, you have the right to withdraw such consent (this will not affect the lawfulness of processing prior to the withdrawal of your consent).

If you wish to exercise any of these rights please contact our Data Protection Officer. Email: dpo@referencepoint.co.uk.

We will inform you (before collecting your data) if we intend to use your data for marketing purposes or if we intend to disclose your information to any third party for such purposes and you can withhold your consent to and prevent such processing by not checking certain boxes on the forms we use to collect your data. You can also exercise the right to prevent such processing at any time by contacting us at support@gosmart.co.uk.

Third Party Links

This notice only applies to our site. If you leave our site via a link or otherwise, you will be subject to the privacy policy of that website provider. We have no control over such policies or terms of such websites and we do not accept any responsibility or liability for them. You should check the relevant policies and terms before continuing to access such sites.

Complaints to Information Commissioner: You have the right to lodge a complaint about our processing with the Information Commissioner.

Consequences of failure to provide personal data: Your provision of personal data to us may be a requirement necessary for you to enter into a contract with us. If you fail to provide certain information when requested, we may not be able to perform the contract we have entered into with you.

Changes to our Privacy Notice

Any changes we may make to our Privacy Notice in the future will be posted on the relevant page on our site and, where appropriate, notified to you by email. However, we advise that you check on our site regularly to keep up to date with any necessary changes.

Cookie Policy

What are cookies?
Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and allows us to improve our site.

A cookie is a small file of letters and numbers that we store on your browser or the hard drive of your computer (or internet-enabled device) if you agree.

Cookies allow us to identify the computer or device you are using to access our website – but we cannot identify you personally. This information is sent back to our systems as you move around our website. Cookies are unique to the web browser you are using – so if you are using a desktop computer as well as a smart phone, different data will be collected for each.

Cookies we use
We use the following cookies:

Strictly necessary cookies: These are cookies that are required for the operation of our website. They include, for example, cookies that enable you to log into secure areas of our website and services.

Analytical/performance cookies: These allow us to recognise and count the number of visitors and to see how visitors move around our site when they are using it e.g. which pages are viewed by visitors most frequently. This helps us to improve the way our website and services work, for example, by ensuring that users are finding what they are looking for easily.

Functionality cookies: These are used to recognise you when you return to our site. This enables us to personalise our content for you and remember your preferences (for example, your choice of language or region).

We do not set targeting/advertising cookies. Cookies are not used in any Apps we provide.

Who sets cookies?
Cookies can be set by the owner of the website you are on. These are known as first party cookies. Please note that third parties may also set cookies of any type, over which we have no control – however, you can control them by managing your cookies (see below). Only the owner of the cookie can see the anonymous information it collects.

How can I manage cookies?
You may block cookies by activating the setting on your browser which allows you to refuse the setting of all or some cookies. However, if you select this setting you may be unable to access all or certain parts of our site.

You can find more information about cookies on the ICO website ico.org.uk/global/cookies and you can find detailed information on how you can control cookies at AboutCookies.org.

We may need to update this Cookie Policy in the future and so encourage you to review this Cookie Policy periodically to stay informed about how we are using cookies. This Cookie Policy was last updated in February 2020.

If you have any questions or comments regarding this Cookie Policy, please email support@referencepoint.co.uk.